Fix panic on out-of-range '@' Unix timestamp in time filters - #2082
Merged
tmccombs merged 2 commits intoAug 9, 2026
Merged
Conversation
Demonstrates that a '@'-timestamp large enough to overflow SystemTime
panics ('overflow when adding duration to instant') instead of being
rejected like other unparseable time inputs. See sharkdp#2081.
Use UNIX_EPOCH.checked_add(...) so an out-of-range value returns None and propagates through the existing ? like every other parse failure in TimeFilter::from_str, rather than panicking via SystemTime's Add. See sharkdp#2081.
nikolauspschuetz
force-pushed
the
fix-changed-time-overflow-panic
branch
from
July 30, 2026 15:06
9a22c99 to
5becb9d
Compare
tmccombs
approved these changes
Aug 9, 2026
tmccombs
marked this pull request as ready for review
August 9, 2026 07:31
This was referenced Aug 9, 2026
1 task
social4hyq
pushed a commit
to social4hyq/homebrew-core
that referenced
this pull request
Sep 20, 2026
fd 10.5.0 Created-by: HarmonybrewBot Commit-by: HarmonybrewBot Merged-by: HarmonybrewBot Description: Created by `brew bump` --- Created with `brew bump-formula-pr`.<details> <summary>release notes</summary> <pre>## Features - Add `--ignore-parent` option to override `--no-ignore-parent`, see #1958 (@tmchow) - Add `--exact` option to match the entire filename exactly (literal, non-substring). ## Bugfixes - Sanitize control characters and bidirectional override characters in filenames when output goes to a terminal, to prevent terminal escape-sequence injection. Also reject a placeholder as the executable for `--exec-batch`, while still allowing it for `--exec`. - Handle invalid working directories gracefully when using `--full-path`, see #1900 (@Xavrir). - Fire the "search pattern contains a path separator" diagnostic for any pattern containing `/`, not just patterns that happen to name an existing directory. Preserves the legacy Windows behaviour that also flags native `\` separators when the pattern resolves to a real directory. See #1873. - Also fire the "search pattern contains a path separator" diagnostic for `--and` patterns, not only the primary positional pattern. `--and` patterns are matched against the file name just like the primary pattern, so a path separator in them silently returned zero results. See #1873. - Fix bug where passing "-" as a directory argument didn't actually search that directory, see #849 (@Sean-Kenneth-Doherty). - Fix panic when `--changed-before`/`--changed-within` is given an out-of-range `@` Unix timestamp; the value is now rejected gracefully, see #2081 (@nikolauspschuetz). ## New Contributors * @liruiluo made their first contribution in sharkdp/fd#1924 * @Xavrir made their first contribution in sharkdp/fd#1917 * @rexkirshner made their first contribution in sharkdp/fd#1921 * @Rohan5commit made their first contribution in sharkdp/fd#1934 * @tmchow made their first contribution in sharkdp/fd#1959 * @YoshKoz made their first contribution in sharkdp/fd#1979 * @SAY-5 made their first contribution in sharkdp/fd#1975 * @skane-lukas made their first contribution in sharkdp/fd#1889 * @Sean-Kenneth-Doherty made their first contribution in sharkdp/fd#2006 * @stevenwalton made their first contribution in sharkdp/fd#2011 * @DeflateAwning made their first contribution in sharkdp/fd#1983 * @wyf027 made their first contribution in sharkdp/fd#2001 * @bonanza127 made their first contribution in sharkdp/fd#2040 * @mahirhir made their first contribution in sharkdp/fd#2036 * @parneetsingh022 made their first contribution in sharkdp/fd#2037 * @curious-rabbit made their first contribution in sharkdp/fd#1976 * @WilliamLeony made their first contribution in sharkdp/fd#2064 * @kobihikri made their first contribution in sharkdp/fd#2063 * @cmelaro made their first contribution in sharkdp/fd#2075 * @nikolauspschuetz made their first contribution in sharkdp/fd#2082 **Full Changelog**: https://github.com/sharkdp/fd/compare/v10.4.2...v10.5.0</pre> <p>View the full release notes at <a href="https://github.com/sharkdp/fd/releases/tag/v10.5.0">https://github.com/sharkdp/fd/releases/tag/v10.5.0</a>.</p> </details> <hr> See merge request: Harmonybrew/homebrew-core!17790
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #2081.
Bug
fdpanics instead of failing gracefully when a@-prefixed Unix timestamp passed to--changed-before/--changed-withinis large enough to overflowSystemTime:Fix
In
src/filter/time.rs, the@-timestamp branch ofTimeFilter::from_strusedUNIX_EPOCH + Duration::from_secs(...);SystemTime'sAdd<Duration>panics on overflow. Every other branch in that function already fails softly via.ok()?— this one didn't.Switched to
UNIX_EPOCH.checked_add(...), which returnsOption, so an out-of-range value propagatesNonethrough the existing?and is rejected like any other unparseable time input (no behavior change for valid timestamps).Test
Added
out_of_range_unix_timestamp_is_rejected, assertingTimeFilter::before/afterwith@{u64::MAX}returnNone. Verified it panics onmasterwithout the fix and passes with it;cargo test --bin fd filter::timeis green andcargo fmt --checkis clean.CHANGELOG updated.
🤖 Disclosure (per CONTRIBUTING §4): the bug was found and the fix drafted with the help of an AI coding assistant; I reviewed it, reproduced the panic and the fails-before/passes-after behavior myself, and understand the change. This PR text is my own.